AI Platform VAPT Checklist
A 12-section, practitioner-grade checklist for scoping and executing penetration tests on LLM apps, RAG pipelines, agents and MLOps — mapped to OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF and ISO/IEC 42001.
Built from real engagements across the UAE, GCC and India — not generic templates.
A practical toolkit for SAQ A, SAQ A-EP and SAQ D environments — covering the new v4.0.1 requirements that became mandatory on 31 March 2025.
Open resourceA 12-week plan for SaaS and managed-service teams to reach a clean Type 2 report, covering the AICPA 2017 Trust Services Criteria with 2022 points of focus.
Open resourceMapping the Central Bank of the UAE Information Security Regulation and Standards to ISO 27001 and PCI DSS, with a 90-day remediation plan for regulated entities.
Open resourceShowing 9 of 9 resources.
A 12-section, practitioner-grade checklist for scoping and executing penetration tests on LLM apps, RAG pipelines, agents and MLOps — mapped to OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF and ISO/IEC 42001.
A practical toolkit for SAQ A, SAQ A-EP and SAQ D environments — covering the new v4.0.1 requirements that became mandatory on 31 March 2025.
A 12-week plan for SaaS and managed-service teams to reach a clean Type 2 report, covering the AICPA 2017 Trust Services Criteria with 2022 points of focus.
Mapping the Central Bank of the UAE Information Security Regulation and Standards to ISO 27001 and PCI DSS, with a 90-day remediation plan for regulated entities.
A 60-point readiness checklist mapped to Annex A 2022 — used by MAST Lead Auditors on every ISO 27001 engagement across the UAE, KSA and India.
A practical control map for the UAE Information Assurance Standards (formerly NESA) — covering all 188 controls across the four priority tiers.
How to stand up an AI Management System under ISO/IEC 42001:2023 — the world's first certifiable AI governance standard.
How NIST RMF, ISO 27005, FAIR, COSO ERM and OCTAVE compare in practice — with guidance on which to pick for cyber, enterprise and AI risk.
A control-by-control checklist for the Abu Dhabi Healthcare Information & Cyber Security Standard V2 — the mandatory baseline for every DoH-licensed entity.
Need something specific?
Tell us what you're working on — readiness assessment, audit prep, board paper — and we'll send the right toolkit (or build one with you).
Request a toolkit